As insider risk grows significantly, federal agencies must adapt from traditional approaches that treat behavior and data separately. These methods have proven to fall short in achieving their mission. Upon the release of Executive Order 13587 Section 2.1b and Section 6, it is time for a new strategy.
During this webinar, attendees learned a next-generation approach to understanding and managing insider risk. Speakers compared the requirements of insider and traditional threat detection techniques and demonstrated practical ways to combine the two using frameworks such as MITRE ATT&CK and MITRE’s behavior-based malicious insider indicators to achieve their objectives of reducing insider incidents.
Attendees heard about:
- The pros and cons of leveraging established cyber frameworks, such as MITRE ATT&CK, for the detection of insider threats.
- The importance of incorporating behavior-based indicators to reduce false positives and make detection algorithms more proactive.
- How to consider the insider threat kill-chain, tactics and techniques to holistically build more effective detections.